AWS Certified DevOps Engineer – Professional (DOP-C02) — Question 188

A company uses Amazon RDS for all databases in its AWS accounts. The company uses AWS Control Tower to build a landing zone that has an audit and logging account. All databases must be encrypted at rest for compliance reasons. The company's security engineer needs to receive notification about any noncompliant databases that are in the company’s accounts.

Which solution will meet these requirements with the MOST operational efficiency?

Answer options

Correct answer: A

Explanation

Option A is the most operationally efficient solution because it leverages AWS Control Tower's built-in capabilities to monitor compliance, minimizing the need for additional custom code or resources. Options B, C, and D involve more complex implementations, such as deploying Lambda functions or creating custom rules, which would require more management and maintenance effort.